What I don't understand
Why would someone who gets the passwords test them out by logging in with them? If the Reg was hacked, why would the hackers login with all of our accounts to test them? If you test a few you know they work, and testing them all would probably set off alarms with some. Plus it isn't like having control of a lot of accounts at a place like this is of any use to anyone.
Now if it was a bank or something, sure, then it would be something they'd test because they'd want to use them.
If they're really seeing 1% of their accounts get logged in to, the real percentage of compromised sites may be much higher!
As for the "well known American startup", that sure sounds a lot like Uber. Another "feather" in their cap...